Splunk architecture considerations
As an organization deploys Splunk, it will have specific requirements related to the architecture, its resiliency, and disaster recovery.
Splunk architecture for an organization
Usage, data volume, and criticality are the three biggest determinants of how much hardware you need in your Splunk environment. If you have large data volumes, a single server may not have enough processor capacity to index and provide searching together. Alternatively, consider the notion of installing Splunk on a single server. If that server were to fail, your Splunk application would fail along with it. If Splunk becomes a critical part of the organization, the cost of server failure may outweigh the costs of more hardware and set-up time to protect against failure.
Splunk provides the ability to configure a multi-tiered environment that can expand and load-balance search and usage activity, separate from indexing and storage activity.
Search capacity
When Splunk executes a search...